CyberRota
Back to database

CVE-2026-8739

MEDIUM · CVSS 5.3 EPSS 0.04% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-17 · Last synced: 2026-06-09

CyberRota Analysis

Uzaktan istismar edilebilir olabilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-8739
Severity
MEDIUM
CVSS
5.3
EPSS
0.04%
Java

Original NVD Description

A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptographic key . The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.